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Quantum entanglement is a key resource in many quantum protocols, such as quantum teleportation 
and quantum cryptography. Yet entanglement makes protocols presented in Dirac notation difficult 
to verify. This is why Coecke and Duncan have introduced a diagrammatic language for quantum 
protocols, called the zx-calculus ifTTl . This diagrammatic notation is both intuitive and formally 
rigorous. It is a simple, graphical, high level language that emphasises the composition of systems 
and naturally captures the essentials of quantum mechanics. In the author's MSc thesis ifTSl it has 
been shown for over 25 quantum protocols that the zx-calculus provides a relatively easy and more 
intuitive presentation. Moreover, the author embarked on the task to apply categorical quantum 
mechanics on quantum security; earlier works did not touch anything but Bennett and Brassard's 
quantum key distribution protocol, BB84. Two of the protocols in 1 18], namely superdense coding 
with the Greenberger-Horne-Zeilinger state and quantum key distribution with the W-state, will be 
presented in this paper. 



1 Introduction 



Quantum protocols are usually described in Dirac notation. Though such a presentation is adequate, it is 
low-level and therefore not a very intuitive formalism. The passage to a high level language was realized 
in Q, by relying on the compositional structure of monoidal categories. Corresponding presentations 
result in the form of quantum picturalism in |[9l[lOl[TTl[T3l, which relies on the diagrammatic presentation 
of symmetric monoidal categories, tracing back to Penrose E7l [22l[29l . 

This diagrammatic notation is both intuitive and formally rigorous. It is a simple, graphical, high 
level language that emphasises the composition of systems and naturally captures the essentials of quan- 
tum mechanics. One crucial feature that will be exploited here is the encoding of complementary ob- 
servables and corresponding phase shifts. Reasoning is done by rewriting diagrams, i.e. locally replacing 
some part of a diagram, according to a few simple rules. Diagrams are defined by their topology only; the 
number of inputs and outputs and the way they are connected. This exemplifies the 'flow' of information. 

Entanglement, described by Einstein as "spooky action at a distance", is a key resource in many 
quantum protocols, like quantum teleportation and quantum cryptography. Yet entanglement makes 
protocols presented in Dirac notation difficult to verify. In the author's MSc thesis lUHl an alternative 
presentation in the zx-calculus of quantum protocols involving the GHZ or the W-state is considered. 
Over 25 different protocols are discussed, such as teleportation, superdense coding (SDC), quantum key 
distribution (QKD) and quantum direct communication. Moreover, the author has embarked on the task 
to apply quantum category theory on quantum security; earlier works did not touch anything but BB84 
lO in O. Two of the protocols in lITSll . SDC and QKD, will be discussed in this paper. SDC was first 
introduced by Bennett and Wiesner in O. In an SDC protocol a number of classical bits is transfered 
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by transferring fewer qubits. In this paper SDC with GHZ as described in Q [T71 will be presented in 
the zx-calculus. Then a QKD protocol making use of the W-state will be presented. In QKD protocols 
a key is shared with two or more people in such a way that they can only retrieve the key if they work 
together. The first quantum key distribution protocol was proposed by Bennett and Brassard in (31 in 
1984 and is generally referred to as the BB84 protocol. After that many other protocols have been 
proposed |[iaill2IMl23IIIll23[M[S|30l. In this paper QKD as described in EB will be discussed. 
To show that a protocol "works", the following definitions will be used. 

Definition 1. A quantum protocol consists of two parts, the set of instructions and the desired be- 
haviour. The set of instructions are the things to be done to achieve the desired behaviour, i.e the goal 
of the protocol. 

Definition 2. A quantum protocol is considered to be correct or valid if the set of instructions leads to 
the desired behaviour 

This paper is organised as follows. First the zx-calculus will be introduced in Sec. [2j Then SDC 
with GHZ will be presented in Sec. [3j after which QKD with W will be discussed in Sec. |4j Finally, 
some concluding remarks will be made in Sec. [5] 



In this section the red/green calculus or the zx-calculus is introduced. For a more thorough and complete 
presentation see |[23l[l2l|l8l or ifTTlQ 

2.1 Components of the zx-calculus 

The zx-calculus consists of components joined by wires, like an electrical circuit. Its components are 
the following: 

1. Z-vertices (green dots), labeled by an angle a G [0,27r), called the phase, with any number of 
inputs and or outputs, zero included. 

2. X-vertices (red dots), complementary to the Z-vertices, labeled by a phase, also with any number 
of inputs, including none. 

3. H-vertices (yellow squares labeled with an H), which represent Hadamard gates. They have exactly 
one input and one output. 

4. \/D- vertices (black diamonds), which represent scalars. These generally don't have any inputs or 



2 The Red/Green Calculus 



outputs. 



The Hilbert space interpretation of these components is as as follows: 
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Figure 1: Basic Rules for the zx-calculus 
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2.2 Quantomatic 

From now on all the pictures (except Fig. [T]) are made with quantomatic |[24ll . a software tool for 
reasoning with the zx-calculus, developed jointly at Oxford, Cambridge, Google and Edinburgh. Dif- 
ferent rule sets can be loaded into quantomatic. One can then input a graph and see what rewrites 
are possible within the loaded rules. Download and installation instructions can be found at http :j 
//sites . google . com/site/quantomatic/home, Using quantomatic to produce the pictures con- 
firms that all the rewrites are valid, but quant omat is does not (yet) provide a way to determine the order 
in which these rewrites should be applied; quantomatic's normalising tool often halts or gets into an 
infinite loop. 

In quantomatic red and green dots are displayed as red and green dots, with their phase in a box 
of corresponding colour underneath the vertex. Hadamard gates are displayed as yellow boxes with an 
H in them. Finally, inputs and outputs are displayed as grey boxes with a number in it, called boundary 
vertices. Quantomatic does not distinguish between inputs and outputs, so they look the same and are 
numbered with the same counter. E.g. a diagram with one input and one output would have one boundary 
vertex with the number zero and one with the number one in it, as in the diagrammatic representation of 
the Hopf law in the next section. Which output or input gets which number is not important and depends 
solely on the order of input in quantomatic. 



2.3 Basic Rules 

Derivations in the Red/Green-calculus are done mostly by a few simple rules, outlined in Fig.[TJ Note that 
rule T does not mean that the topology is always preserved; other rules might change this completely. 
Informally T can be seen as "yanking" the wires, making sure the number of inputs and outputs is 
preserved and the way they are connected. 

An addition to these rules has been made by Kissinger in ll23l and Coecke and Edwards in |[T2ll . 
These two related rules that are called |0)- and supplementarity were found by solving a matrix 
equation in ll23l and by means of the underlying algebraic structure in |[T2l . 
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From now on scalars will be left out for sake of simplicity. Note also that quantomatic does not 
include scalars in the rewrites. 

A useful derivation from the basic rules is the Hopf law: 
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Another useful derivation, used later on is the following: 
Lemma 2. 
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Proof. 
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2.4 Measurements into the x- and z-basis 

The graphical representation of measurements or "effects" into the x- and z-basis can be derived by 
the Hilbert space interpretation of points. |+) (\x'^)) and |— ) (\x~)) and |0) ([z"*")) and |l)(|z~)) are 
represented as 
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2.5 The GHZ state 

The GHZ state is one of the only two SLOCC-inequivalent classes of tripartite entanglement |fT5^. 
SLOCC-inequivalent means inequivalent under Stochastic Local Operations and Classical Communi- 
cation, i.e. one cannot be turned into the other by means of stochastic local operations (unitaries and or 
measurements) and classical conmiunication. GHZ is defined as \GHZ) — ;^(|000) + | 111)), or as the 
map 

'|0)^|00) 
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Graphically it is represented as ifTll 



Plugging |0) and |1) gives 
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as required. 
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2.6 The W-state 

The class of W-states is SLOCC-inequivalent to the class of GHZ states lfT5l . The W -state is defined as 

|W) = -^(1001) + 1010) + I100)), 



or as the map 123 



W :: 



|0) H-> |01) + |10) 

|1) |00). 



Considering this map, the W-state can be graphically represented as ||23 
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This graphical representation shows the robustness of the W-state; due to the pairwise entanglement, 
after tracing out one of the qubit, there is still the possibility of bipartite entanglement, as opposed to the 
GHZ state, which is fully separable when any of the qubits is traced out. Plugging |0) in Eq. [7] gives 
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as expected. Plugging |1) in Eq.|7] gives 
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as required. 



2.7 The Pauli Matrices 

By the Hilbert space interpretation, one can obtain the representation of the Pauli-Z and Pauli-X matrices 
in zx-calculus: 
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Once the Pauli-X and Z matrices are known, it is easily deduced that iOy = 0^x0^ = 0^00^ and 
-iOy = 0x^0^ = 0x0 0^ are compositions of Ox and o^. 
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2.8 Controlled Not gate 



Another useful tool is the Controlled Not gate. 



The Controlled Not gate is defined as follows: 
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3 Superdense Coding with GHZ 

As with Bell states, it is possible to transfer an amount of classical bits by transferring fewer qubits by 
means of different states in the GHZ class. When states in the GHZ class are used for super dense coding, 
two qubits need to be transfered in order to transfer three classical bits [7J. This section is divided up in 
five subsections. First the steps of the protocol will be explained. Then the eight different states in the 
GHZ class will be presented. In the last three subsections it will be shown how, through measurement in 
the GHZ basis, these eight different states can be translated into three classical bits, proving the validity 
of the protocol. 

3.1 Super Dense Coding with GHZ protocol 

Provided Alice and Bob share \GHZ), such that the first qubit belongs to Bob and the other two qubits 
belong to Alice, the following protocol describes superdense coding with GHZ as in llTlfTT]!: 

1. Alice applies a combination of /, <7x, iOy and on both her qubits, encoding one of eight distin- 
guishable states in the GHZ class. 

2. Alice transfers both her qubits to Bob. 

3. Bob measures all three qubits in the GHZ basis, retrieving the state Alice encoded. 

4. Bob translates the retrieved state to three classical bits. 

3.2 Different GHZ states 

There are eight different states in the GHZ class. One can go from one to the other by performing unitary 
single particle operations on two of the three particles. These unitary operations are /, (7x,/cjy and a^. 
Though there are 16 different combinations of these operators on two qubits, only half of them generate 
distinguishable states [ 31 J as can be seen by comparing the graphical representations in Table [T] and [2] in 
Appendix |A| In this section we will work with states in the standard form 




(11) 



as in lOITll, where ij E {0, 1}, / = 1 — / and j = 1 — j. 
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3.3 Encoding a GHZ measurement outcome into classical bits 

The encoding is as in |[6l. After measurement, an output qubit is encoded as if it is |0) and as 1 if it 
is| 1). Every GHZ state gives three output bits. If the first output bit is 0, then there is an odd number 
of 1+) in the basis, otherwise an even number. If the second output bit is 0, then the first two bits in the 
GHZ class state are the same, otherwise they are different. And finally, if the last output bit is 0, the last 
two bits in the GHZ class state are the same. This encoding is displayed in Table [T] in Appendix [A| 



3.4 Measurement into the GHZ basis 

The circuit to measure into the GHZ basis is ^ 



m m m 



(12) 



which gives three qubits in the z-basis. Plugging states in the z-basis, we obtain for a, j8 , 7 E {0, n} 
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which results in one of eight states in the GHZ class upside down by Table [T] and [2] in Appendix [A| if 
values for a, j8 and 7 are set. 



3.5 Validity of the protocol 

Lemma 3. The encoding in combination with the GHZ measurement circuit in [6] makes for a valid 
Superdense Coding protocol^ 



Proof. Let |0) = and 1 1) = 1 in classical bits. What needs to be shown is that for all eight states in the 



^Note that this encoding is different from ITtIITtI. 
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GHZ class, their measurement outcome is equal to their binary representation in Table [T] in Appendix [A) 
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= |110) = 110 = 6 (20) 
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111) 



111 =7. 



(21) 



Eg. [T4pT] imply the validity of the protocol. 



□ 



3.6 Superdense coding with N-GHZ 

In a similar way superdense coding for N-GHZ states can be constructed. One of {/, dx, /(Jy, CJ^} can be 
applied on the N^^ qubit and one of {/, <7^} on qubit 2 — (A/^ — 1) to encode 2^ different states. They can 
be distinguished with a measurement like the GHZ basis measurement [i6j|. 

4 Pairwise Quantum Key Distribution with W3 

In this section the Quantum Key Distribution protocol with W3 from II2TII will be explained. It will 
moreover be shown by means of the zx-calculus that this protocol works. 

4.1 Pairwise Quantum Key Distribution with W3 protocol 

Alice, Bob and Charlie share a series of W3 -states in the Pairwise Quantum Key Distribution with W3 
protocol and perform measurements on their qubits in such way that two of them will share a common 
(classical) key. Assuming they share a series of Ws-states, the protocol can be established as follows: 

1. All choose at random the x- or the z-basis to measure their qubit in. 

2. Each announces publicly his or her measurement direction. 

3. For security reasons, they randomly choose to announce their measurement outcomes, to check 
for eavesdropping. If they do, the protocol is restarted. 

4. If the overall measurement basis isz — x — x,x — z — xorx — x — z, they continue with the protocol. 
Otherwise they start over and discard these measurement outcomes. 

5. The one who measured along the z-axis is the decider. S/he tells the others whether the outcome 
is (z^|. Otherwise they restart the protocol. 

6. The other two now know that they have the same outcome, i.e. they share a bit now. 

7. Repeat the protocol until the desired amount of key bits are obtained. 

8. Use the information from step[3]to check for eavesdropping. If eavesdropping is detected, discard 
the obtained key bits and start a new quantum channel to repeat the protocol. 
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1. Measurement ^ 
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Figure 2: Graphical representation of the set of instructions of the Pairwise Quantum Key Distribution 
with W3 protocol, a, G 0, tt 



Lemma 4. F/g. |2]/^ the graphical representation of the set of the instructions of the Pairwise Quantum 
Key Distribution with W3 protocol, when the first two measurements are in the z- and x-basis. 



Proof Box 1 is a measurement in the x-basis, box 2 is a measurement into the z-basis. Box 3 is the 
W3 -state. □ 



Lemma 5. If any one of them gets the outcome {z \ the entanglement will be broken and the outcomes 
for the other two will be (z+ 1. 



Proof Setting b = 7t, then by Eq[9j 



□ 



Lemma 6. When there is a proper overall measuring basis and the decider has the outcome (z+|, the 
other two always have the same result. 
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□ 



Corollary 7. T/z^ Pairwise Quantum Key Distribution with W3 protocol is correct. 

5 Conclusions 

In this paper two of the 25 plus quantum protocols in [ 18 1 have been presented in the zx-calculus. It has 
been shown that they are both valid protocols, by means of easy manipulations of their diagrammatic 
representation. Producing the diagrammatic representation of a protocol is a matter of "gluing" together 
basic constructions, such as CNOT gates. Bell states and measurements. The more of these basic con- 
structions are known, the easier this becomes. Many of these basic constructions can be found in the 
author's MSc thesis, along with examples in which they are used 1 18 |. After this representation has been 
found, the correctness of a protocol can be shown by a few simple manipulations of the diagrams. From 
this it can be concluded that the red/green calculus provides a clear and intuitive way to represent and 
check quantum protocols. 

Though not explicitily discussed here, it turns out that it is difficult to check the security of many 
protocols by means of the zx-calculus. This is because detection of eavesdropping or disturbance often 
depends on the probability of obtaining illegal measurement outcomes after the quantum channel is inter- 
fered with. Although it is easy to plug different measurement outcomes in the diagrammatic notation, it 
is not always possible to calculate what combinations of measurement outcomes are possible. Moreover 
one cannot calculate the probability of different combinations of measurement outcomes from the dia- 
grammatic notation, because in the implementation of the the zx-calculus, quant omatic l[24ll . scalars 
are ignored. 

One can conclude from this, that a presentation in either Dirac notation or the zx-calculus is not 
optimal. Instead, a combined approach should be taken. The zx-calculus provides a simple and intuitive 
way to understand the workings of the protocol and Dirac notation is helpful to check the security of 
protocols. 
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A The Graphical representation of GHZ class States 
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Table 1: This table shows the eight different states in the GHZ class, their binary presentation, the 
unitaries that should be applied to the second and the third qubit to obtain this state from \GHZ) and 
finally their graphical representation. 
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Table 2: This table shows the remaining states in the GHZ class, their binary presentation, the unitaries 
that should be applied to the second and the third qubit to obtain this state from \GHZ) and finally their 
graphical representation. 



